Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Council on Foreign Relations

Council on Foreign Relations Vendor Cyber Rating & Cyber Score

cfr.org

The mission of the Council on Foreign Relations is to inform U.S. engagement with the world. Founded in 1921, CFR is a nonpartisan, independent national membership organization, think tank, educator, and publisher, including of Foreign Affairs. It generates policy-relevant ideas and analysis, convenes experts and policymakers, and promotes informed public discussion—all to have impact on the most consequential issues facing the United States and the world. CFR's website, www.cfr.org, is a trusted, nonpartisan source of timely analysis and context on international events and trends. CFR publishes the bimonthly Foreign Affairs magazine, widely-considered to be the most influential magazine for the analysis and debate of foreign policy and


CFR A.I CyberSecurity Scoring

CFR
Company Information
Website:http://www.cfr.org
Employees number:2,156
Number of followers:399,097
NAICS:54172
Industry Type:Think Tanks
Homepage:cfr.org
CFR Risk Score (AI oriented)
Between 750 and 799
logo
CFRThink Tanks
Updated:
03/04/2026
769/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CFR Global Score (TPRM)
xxxx
logo
CFRThink Tanks
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CFRFair
Current Score
769Baa (FAIR)
01000
2 incidents
-8 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
754Before Incident
AUGUST 2026
769Before Incident
JULY 2026
769Before Incident
JUNE 2026
769Before Incident
MAY 2026
769Before Incident
APRIL 2026
769Before Incident
Vulnerability
07 Apr 2026CFR
TP-Link: Russian APT28 Hackers Hijack Routers to Steal Credentials

Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign

768After Incident
CRITICAL-1
TP-1775579951
Russian APT28 Exploits Vulnerable Routers in Large-Scale Credential Theft Campaign The UK’s National Cyber Security Centre (NCSC) has issued a warning about two ongoing cyberespionage campaigns by the Russian hacking group APT28 (also known as Fancy Bear, Forest Blizzard, and Sofacy), which is linked to Russia’s GRU military intelligence unit. Since early 2024, APT28 has been hijacking vulnerable internet routers particularly TP-Link models to redirect traffic through attacker-controlled servers and steal credentials from targeted organizations. ### How the Attack Works APT28 has repurposed virtual private servers (VPS) as malicious DNS servers, intercepting high volumes of DNS requests from compromised routers. The group employs an opportunistic approach, initially casting a wide net to identify potential victims before narrowing down targets of intelligence value. In one campaign, APT28 exploited CVE-2023-50224, a vulnerability in TP-Link WR841N routers that allows unauthenticated attackers to extract credentials via crafted HTTP requests. By altering the DHCP DNS settings on these routers, the group forced downstream devices (such as laptops and phones) to resolve requests through their malicious servers. This enabled adversary-in-the-middle (AitM) attacks, allowing APT28 to harvest passwords, OAuth tokens, and other credentials from web and email services. Microsoft Threat Intelligence further reported that APT28 and its sub-group Storm-2754 have been compromising SOHO routers since at least August 2023, expanding their infrastructure to facilitate these attacks. ### Impact and Attribution The NCSC assesses that APT28’s operations are highly targeted, focusing on entities of strategic interest to Russian intelligence. While the initial router compromises appear broad, the group refines its focus at later stages to prioritize high-value victims. The stolen credentials could enable further unauthorized access, though the exact scope of follow-on attacks remains unclear. This campaign underscores the persistent threat posed by state-backed cyber actors leveraging common vulnerabilities in consumer-grade networking devices to conduct large-scale espionage.
INCIDENT DETAILS -
TYPE
Cyberespionage
MOTIVATION
Cyberespionage, credential theft for intelligence gathering
IMPACT
Data Compromised: Passwords, OAuth tokens, credentials from web and email servicesSystems Affected: TP-Link WR841N routers, downstream devices (laptops, phones)Identity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials (passwords, OAuth tokens), web and email service dataSensitivity Of Data: High (personally identifiable information, authentication tokens)Data Exfiltration: YesPersonally Identifiable Information: Yes
MARCH 2026
769Before Incident
FEBRUARY 2026
769Before Incident
JANUARY 2026
769Before Incident
Cyber Attack
01 Jan 2026CFR
FBI: Russia used social engineering to breach prominent messaging accounts, Ukraine says

Russian Cyber Espionage Campaign Targets Government, Military, and Activists Across Ukraine, Europe, and the U.S.

754After Incident
CRITICAL-15
FBI1782484133
Russian Cyber Espionage Campaign Targets Government, Military, and Activists Across Ukraine, Europe, and the U.S. Ukraine’s Security Service (SBU), in collaboration with the FBI, has uncovered a prolonged Russian cyber espionage campaign aimed at compromising the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the United States. The operation, designed to extract sensitive military, political, and economic intelligence, also sought to steal victims’ personal data. Rather than exploiting vulnerabilities in messaging apps, attackers relied on social engineering tactics. One common method involved sending fraudulent text messages often in the early morning posing as official support services to trick users into revealing account credentials. The SBU noted that victims were particularly vulnerable during these hours due to fatigue or distraction. Targets included Ukrainian government institutions, public officials, activists, and civilians, though the SBU did not disclose the specific Russian intelligence service behind the campaign, the primary messaging platforms affected, or the total number of victims. The FBI has not yet commented on the investigation. The disclosure aligns with previous warnings from Ukraine and Western intelligence agencies about Russian efforts to infiltrate secure messaging platforms. Earlier this year, Dutch authorities reported a global campaign by Russian state-backed hackers to hijack Signal and WhatsApp accounts belonging to government, diplomatic, and military personnel, often by impersonating customer support to obtain verification codes or PINs. Ukraine has repeatedly documented Russian espionage operations targeting military communications, including malware designed to steal data and attempts to extract encrypted Telegram and Signal messages from devices recovered on the battlefield.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Espionage, Intelligence Gathering
IMPACT
Data Compromised: Sensitive military, political, and economic intelligence; personal dataSystems Affected: Messaging accounts (unspecified platforms)Identity Theft Risk: High
DATA BREACH
Military intelligencePolitical intelligenceEconomic intelligencePersonal dataSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
DECEMBER 2025
769Before Incident
NOVEMBER 2025
769Before Incident
OCTOBER 2025
769Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CFR ?
?
What was CFR's A.I Rankiteo Cyber Score in August 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in July 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CFR's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CFR's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CFR's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on CFR's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CFR ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CFR's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?